Privacy Policy
Last updated: 5 August 2026
Knudge ("Knudge", "we", "us") provides AI-powered chat, voice, and phone agents that businesses ("Customers") embed on their websites and phone lines. This policy explains what personal data we process, why, and the rights you have. It covers both our Customers (workspace users of app.knudge.nex0.tech) and the people who talk to our Customers' agents ("Visitors").
1. Who is responsible for your data
For workspace accounts, Knudge is the data controller. For conversations a Visitor has with a Customer's agent, the Customer is the controller and Knudge acts as a processor on the Customer's behalf and instructions.
2. Data we process
- Account data — name, email address, password hash, workspace membership, and billing records.
- Conversation data — messages, voice-call transcripts and audio, ratings, and any details a Visitor chooses to share (for example an email address to book a meeting).
- Visitor context — pages viewed on the Customer's site, approximate location derived from IP, browser type, and an anonymous visitor identifier. We do not build cross-site profiles.
- Memories — short factual notes the agent extracts to serve returning Visitors better (e.g. "prefers email contact"). Customers can view and delete these at any time.
- Usage & payment data — metering of AI usage for billing, processed via Stripe. Knudge never stores full card numbers.
3. Why we process it (legal bases)
- To provide the service (performance of contract).
- To bill and prevent abuse (contract, legitimate interests).
- To improve agent quality — e.g. when a human corrects an AI reply, the difference may be used to improve that Customer's own agent. Data is never used to train models for other customers (legitimate interests / Customer instructions).
- To comply with law (legal obligation).
4. AI transparency
Conversations with a Knudge agent are AI-generated unless a human explicitly takes over. Agents always disclose that they are AI. Voice agents state this at the start of a call. AI outputs may be imperfect; Customers remain responsible for reviewing critical information.
5. Where data lives and our subprocessors
Customer and conversation data is stored in the European Union (AWS, eu-central-1, Frankfurt). To run the service we use a small set of subprocessors, each bound by data-processing agreements:
- Amazon Web Services (EU) — hosting, storage, encryption
- Stripe — payments
- xAI — language-model responses
- Groq — fallback language-model responses
- Deepgram — speech-to-text
- ElevenLabs — text-to-speech
- Telnyx — phone calls and SMS
- Cal.com — meeting scheduling (when the Customer connects it)
- Slack — notifications (when the Customer connects it)
- Vercel — web-app delivery
Some AI subprocessors are located in the United States; transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. Only the minimum conversation content needed to generate a reply is sent.
6. Encryption & security
Data is encrypted in transit (TLS 1.2+) and at rest. Sensitive workspace content (style profiles, learning-loop drafts, integration keys) is additionally encrypted with a per-workspace key using envelope encryption (AWS KMS). Access by our staff is limited, logged, and audited.
7. Retention
Conversation data is retained while the Customer's workspace is active or until the Customer deletes it. Customers can purge Visitor data (including memories) at any time. Closed accounts are deleted within 90 days, except records we must keep for tax or legal reasons.
8. Your rights
Under the GDPR you may request access, correction, deletion, restriction, portability, or object to processing. If you spoke with an agent on a Customer's site, contact that Customer first — we support them with erasure tooling that scrubs your messages, memories, and identity. You may also contact us directly and lodge a complaint with your supervisory authority.
9. Cookies
The Knudge app uses strictly necessary cookies (session sign-in). The embeddable widget uses local storage for an anonymous visitor ID and does not use advertising cookies or cross-site tracking.
10. Children
Knudge is not directed at children under 16 and we do not knowingly collect their data.
11. Changes
We will post any changes here and update the date above. Material changes are announced to Customers by email or in-app notice.
12. Contact
Data protection inquiries: privacy@knudge.nex0.tech. Postal address available on request.